Quiet Guard
WordPress plugin to report PHP errors, exceptions and fatal shutdowns to a Quiet Guard server.
by Alexandre Ribes · github.com/quiet-guard/monitor-wordpress · website
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/quiet-guard/monitor-wordpress/archive/refs/heads/main.zipReadme
Quiet Guard: WordPress plugin
Report PHP errors, exceptions and fatal shutdowns from a WordPress site to your
Quiet Guard server.
Built on the framework-agnostic core quiet-guard/monitor-php, the same
engine that powers the Laravel SDK and the Symfony bundle.
The WordPress.org distribution file is readme.txt; this page is the developer view.
Requirements
- WordPress 6.0+
- PHP 8.2+ with
ext-curlandext-sodium(required by the core)
Build and install
The plugin vendors the monitor core through Composer, so it must be built
before it is uploaded. Clone this repository INTO a folder named
laravel-monitor: WordPress takes the plugin's slug from its folder, and the
zip has to carry that name.
git clone https://github.com/Quiet-Guard/monitor-wordpress laravel-monitor
cd laravel-monitor
composer install --no-dev
cd .. && zip -r laravel-monitor.zip laravel-monitor
Upload the zip in wp-admin (Plugins, Add New, Upload Plugin) or drop the folder
under wp-content/plugins/, then activate it. An unbuilt folder (no vendor/)
activates safely: the plugin captures nothing and shows an admin notice.
Configuration
Go to Settings → Quiet Guard and fill in:
- Enabled: master switch (1/0).
- Server URL: optional, and empty means the hosted service at
https://quietguard.dev, so a site on it only has to paste its key. Fill it to
reach a self-hosted instance. A value that already
ends in
/apior/api/v1is accepted and normalised. - Project key: the per-project API key generated in the dashboard (shown only once at creation).
- Environments and Release: optional metadata attached to reports.
Two advanced keys, timeout (default 3 seconds) and trace_limit (default 0 =
full stack trace, like every client in the family), are read from the same
laravel_monitor_options option and can be set programmatically via
update_option(); they survive settings-screen saves.
What it captures
- Uncaught PHP exceptions, PHP errors at
E_USER_ERRORorE_RECOVERABLE_ERROR(within the configurederror_reportinglevel), and fatal shutdowns. Warnings and notices are not reported: every severity used to be forwarded as one synchronous POST each, which turns a warning inside a loop into hundreds of blocking calls on a page load. The same error on the samefile:lineis reported once per request, twenty errors per request at most. - Capture is additive: WordPress' own error handling still runs, and reporting failures never break the site.
- Context values are scrubbed by key (passwords, tokens, cookies...) before anything leaves the site, and stack-trace frame arguments are never sent.
- The plugin writes its own diagnostics with
error_log(), so a wrong key, a wrong address or a refused payload leaves a[Quiet Guard]line inwp-content/debug.logwhereverWP_DEBUG_LOGis on.
Application log forwarding and dependency/vulnerability scanning for WordPress are on the roadmap and not part of this plugin yet.
Documentation
Full documentation is served by your Quiet Guard server under /docs
(for example https://monitor.example.com/docs), including a dedicated
section for this plugin.
License
MIT. See LICENSE.